vendor:
Acropolis Operating System
by:
Adam Brown
9.8
CVSS
CRITICAL
SFTP Authentication Bypass
Unknown
CWE
Product Name: Acropolis Operating System
Affected Version From: Unknown
Affected Version To: < 5.5.5 (LTS), < 5.8.1 (STS)
Patch Exists: NO
Related CWE: CVE-2018-7750
CPE: Unknown
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-7750/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-7750/
Platforms Tested: Acropolis Operating System
2018
Nutanix AOS & Prism – SFTP Authentication Bypass
The Acropolis SFTP server doesn't check if the client has completed the authentication step before allowing the client to open channels. This allows an attacker to list the root directory without authenticating.
Mitigation:
Unknown